typedef struct _STATIC_FILTER
{
ULARGE_INTEGER m_Adapter;
DWORD m_dwDirectionFlags;
DWORD m_FilterAction;
DWORD m_ValidFields;
DWORD m_LastReset;
ULARGE_INTEGER m_PacketsIn;
ULARGE_INTEGER m_BytesIn;
ULARGE_INTEGER m_PacketsOut;
ULARGE_INTEGER m_BytesOut;
DATA_LINK_LAYER_FILTER m_DataLinkFilter;
NETWORK_LAYER_FILTER m_NetworkFilter;
TRANSPORT_LAYER_FILTER m_TransportFilter;
} STATIC_FILTER, *PSTATIC_FILTER;
The _STATIC_FILTER structure defines a kernel-mode filtering rule in Windows Packet Filter. Rules can inspect data link layer (Ethernet), network layer (IPv4/IPv6), and transport layer (TCP/UDP/ICMP) headers.
m_Adapter
Specifies the network adapter for which this filter is applied. Set to 0 (QuadPart = 0) to apply to all adapters.
m_dwDirectionFlags
Specifies packet direction for evaluation: PACKET_FLAG_ON_SEND, PACKET_FLAG_ON_RECEIVE, or both.
m_FilterAction
Determines the action taken by ndisrd.sys when a packet matches the filter:
FILTER_PACKET_PASS(0x00000001): Passes packet through its normal network processing path.FILTER_PACKET_DROP(0x00000002): Drops the packet immediately in kernel mode.FILTER_PACKET_REDIRECT(0x00000003): Diverts the packet to the user-mode application queue/Fast I/O section.FILTER_PACKET_PASS_RDR(0x00000004): Passes the packet through normal processing AND delivers a copy to the user-mode application (ideal for passive monitoring/sniffing without forwarding latency).FILTER_PACKET_DROP_RDR(0x00000005): Drops the packet from the network BUT delivers a copy to user mode (ideal for security inspection and forensic logging of blocked traffic).
m_ValidFields
Bitmask indicating which layers are evaluated: DATA_LINK_LAYER_VALID (0x01), NETWORK_LAYER_VALID (0x02), TRANSPORT_LAYER_VALID (0x04).
m_LastReset, m_PacketsIn, m_BytesIn, m_PacketsOut, m_BytesOut
Filter statistics tracked in kernel mode. m_LastReset records the timestamp (seconds since Jan 1, 1980) of the last counters reset. m_PacketsIn and m_BytesIn record cumulative incoming packets and bytes that matched this filter; m_PacketsOut and m_BytesOut record cumulative outgoing packets and bytes that matched this filter.
m_DataLinkFilter, m_NetworkFilter, m_TransportFilter
Layer-specific filter definitions specifying MAC, IP, and port/protocol match criteria.
See Also
AddStaticFilterFront, AddStaticFilterBack, InsertStaticFilter, _STATIC_FILTER_WITH_POSITION, _STATIC_FILTER_TABLE, Managing Individual Static Filters